CVE-2026-53553: Zhenorzz Goploy
High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by the client. This issue has been patched in version 1.18.0.
Affected products
- Zhenorzz Goploy: before 1.18.0 (fixed in 1.18.0)
Published 2026-08-31. Last modified 2026-09-08.